FHI MCP Server Security Audit

Free payment guide and Base-USDC x402 MCP security, package, domain, and SEC tools.

我該用這個嗎

品質與安全性

B
說明品質
87%
結構描述完整度
72%
命名品質
80%
汙染風險
100%
權限相符程度
100%
協定合規性
100%

發現項目(2)

  • LOWTool 'payment_info' description lacks action verb在 payment_info 中
  • LOWTool 'sec_material_event_delta' description lacks action verb在 sec_material_event_delta 中

根據工具定義與協定合規性的自動化分析。

上下文成本

~682Token(工具定義)
~584 B典型回應大小
中等的注意力影響(128k 上下文的 0.53%)

這是每次將伺服器的工具載入模型上下文時所消耗的約略 token 數量。數量越高,可用於其他工作的注意力就越少。

安裝

一鍵安裝

將以下內容加入你的 `claude_desktop_config.json` 檔案:

{
  "mcpServers": {
    "fhi-x402-security-tools": {
      "url": "https://polished-truth-c514.fhi-llc-1118.workers.dev/mcp"
    }
  }
}

遠端端點

https://polished-truth-c514.fhi-llc-1118.workers.dev/mcpstreamable-http

它能做什麼

工具清單

工具(6)

🟢 唯讀🟡 寫入🔴 刪除⚪ 未知
⚪payment_info

Free guide to the FHI MCP tools, Base-USDC x402 payment flow, and per-tool prices.

輸入結構描述

{
  "type": "object",
  "properties": {}
}
🟡domain_change_evidence(domain)

Stateful DNS, CAA, and certificate-transparency monitoring for a public domain. The first call establishes a baseline; later calls return evidence changes and certificate-expiry signals. ($0.01 USDC on Base)

輸入結構描述

{
  "type": "object",
  "properties": {
    "domain": {
      "type": "string",
      "minLength": 1
    }
  },
  "required": [
    "domain"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪package_install_preflight(ecosystem, name, version, expectedName)

npm or PyPI install preflight: blocks missing packages, detects near-name typosquats when an expected name is supplied, and checks OSV advisories. ($0.01 USDC on Base)

輸入結構描述

{
  "type": "object",
  "properties": {
    "ecosystem": {
      "type": "string",
      "enum": [
        "npm",
        "PyPI"
      ]
    },
    "name": {
      "type": "string",
      "minLength": 1
    },
    "version": {
      "type": "string"
    },
    "expectedName": {
      "type": "string"
    }
  },
  "required": [
    "ecosystem",
    "name"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪sec_material_event_delta(cik, ticker, since)

New SEC 8-K, 6-K, and late-filing evidence since a cursor date; accepts a ticker or CIK. ($0.01 USDC on Base)

輸入結構描述

{
  "type": "object",
  "properties": {
    "cik": {
      "type": "string"
    },
    "ticker": {
      "type": "string"
    },
    "since": {
      "type": "string",
      "minLength": 1
    }
  },
  "required": [
    "since"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪mcp_payment_preflight(serverUrl)

MCP server security audit before an agent connects or pays: probes initialize and tools/list, then returns an ALLOW, CAUTION, or BLOCK risk score for command, filesystem, or wallet capabilities; prompt-injection or data-exfiltration signals; permissive JSON-schema inputs; missing HSTS; and a large tool surface. Does not execute tools. ($0.01 USDC on Base)

輸入結構描述

{
  "type": "object",
  "properties": {
    "serverUrl": {
      "type": "string",
      "format": "uri"
    }
  },
  "required": [
    "serverUrl"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}
⚪mcp_vendor_due_diligence(mcpUrl, ticker, cik, since)

One decision-ready due-diligence dossier before an agent adopts or pays an MCP vendor: live MCP metadata and tool-risk preflight, DNS/CAA/certificate evidence, plus optional SEC material-filing evidence for a public company. Does not execute vendor tools or certify safety. ($0.10 USDC on Base)

輸入結構描述

{
  "type": "object",
  "properties": {
    "mcpUrl": {
      "type": "string",
      "format": "uri"
    },
    "ticker": {
      "type": "string"
    },
    "cik": {
      "type": "string"
    },
    "since": {
      "type": "string"
    }
  },
  "required": [
    "mcpUrl"
  ],
  "additionalProperties": false,
  "$schema": "http://json-schema.org/draft-07/schema#"
}

社群

為此伺服器評分

證據

近期觀測

已驗證未記錄版本6 個工具